Cookezee

Privacy Policy

Last Updated: 18 August 2026


1. WHO WE ARE

This Privacy Policy explains how CookEzee Services LLP ("CookEzee", "We", "Us"), operating the CookEzee mobile application and related services (the "Platform"), collects, uses, shares, and protects Your personal data. By creating an account or using the Platform, You ("You", "User", a Customer or a Cook Partner) acknowledge this Policy.

This Policy is a Supplemental Term to, and forms part of, Our Terms and Conditions.

About CookEzee. CookEzee Services LLP operates an on-demand marketplace that connects customers in Bangalore with independent, verified home cooks ("Cook Partners") for instant, scheduled, and monthly home-cooking services. We are a technology intermediary; the cooking is performed by the Cook Partners in the customer's kitchen.

Who this Policy applies to. This Privacy Policy applies to all users of the Platform, namely: (a) Customers who book cooking services; (b) Cook Partners who register to offer cooking services; and (c) visitors to Our website and app. By accessing or using the Platform in any of these capacities, You acknowledge this Policy.


2. PERSONAL DATA WE COLLECT

Category Examples When
Identity & contact Name, mobile number (verified via OTP), email Registration
Cook KYC (Cook Partners only) Aadhaar (front/back), selfie, bank account details, certificates Cook onboarding
Location GPS coordinates, derived pincode/locality While using the app; live GPS only while a Cook is travelling to a booking
Booking & transaction Booking details, address, amounts, payment status, ratings When You book / cook
Payment Processed by our payment partner; We store payment status and tokens, not full card numbers At payment
Device & usage Device identifiers, IP address, FCM push token, app interactions, logs Automatically
Communications In-app chat, call records / metadata between You and the other party to a booking, and Your correspondence with support When You communicate through the Platform or with support

We collect only what is needed to provide the Services (data minimisation).

Customers vs Cook Partners. From Customers We collect identity and contact details, service location / address, booking and transaction data, payment status, communications, and device / usage data. From Cook Partners We additionally collect KYC and verification data, namely Aadhaar, PAN, a photograph / selfie, bank-account details, certifications, address proof, and background-verification consent, needed to onboard, verify, and pay them.


3. HOW WE USE YOUR DATA (PURPOSES)


4. LEGAL BASIS / CONSENT (DPDP Act)

We process personal data based on Your consent (given at registration and via in-app actions) and for legitimate uses permitted under the DPDP Act (e.g. fulfilling a service You requested, complying with law). You may withdraw consent at any time (Section 8); withdrawal may prevent Us from providing some or all Services.


5. WHO WE SHARE DATA WITH

We share personal data only with the following categories of recipients, and only to the extent necessary:

We do not sell Your personal data. We require the processors We engage to protect it and to use it only for the purposes We specify.


6. DATA RETENTION

We retain personal data only as long as needed for the purposes above or as required by law (e.g. tax, KYC, dispute records). Live location pings are deleted as soon as a booking's travel phase ends. On account deletion, We delete or anonymise data not required to be retained by law.

Cook Partner offboarding. When a Cook Partner leaves or is removed from the Platform, We deactivate their profile and delete or anonymise their personal data, except records We are required to retain by law (for example, KYC, tax, payout, and dispute records) for the period prescribed.


7. SECURITY & STORAGE OF DATA

We store personal data on secured, access-controlled cloud infrastructure (Google Firebase). We apply reasonable technical and organisational safeguards, including firewalls, encryption of data in transit (TLS / HTTPS), scoped database access rules, role-based access controls, and payment tokenisation (We do not store full card numbers). No method of transmission or storage is 100% secure; You share data at Your own risk and must keep Your account credentials confidential. In the event of a personal-data breach likely to affect You, We will notify You and the Data Protection Board of India as required under the DPDP Act.


8. YOUR RIGHTS (DPDP Act)

Subject to the DPDP Act, You may:

To exercise any right, contact the Grievance Officer below. We will respond within the timelines required by law.


9. GRIEVANCE / DATA PROTECTION OFFICER

Privacy questions, requests, and complaints under the DPDP Act are handled by Our grievance function, reachable at the contact details below. The name and direct phone number of the designated Data Protection Officer / Grievance Officer will be published here once appointed.

We will acknowledge and resolve grievances within the timelines prescribed under applicable law (typically within 30 days). If unsatisfied, You may approach the Data Protection Board of India.


10. CHILDREN

The Platform is not intended for individuals under 18. We do not knowingly collect data from children. If We become aware that We have inadvertently collected personal data from a child, We will delete it.


11. COOKIES & WEBSITE ANALYTICS

Our website (cookezee.com) uses cookies and similar technologies, along with third-party analytics, including PostHog (product analytics and session insights) and Google Fonts, to understand how the site is used, improve it, and remember preferences. You can control or block cookies through Your browser settings; some site features may not work if You disable them. Our mobile app relies on device identifiers and push tokens rather than browser cookies. Our servers and analytics providers also automatically log technical data such as Your IP address, browser and device type, referring page, and pages visited, to keep the Platform secure and to diagnose and improve it.


12. INTERNATIONAL DATA TRANSFER

Some of Our service providers (for example, Google Firebase and analytics providers) may store or process data on servers located outside India. Where personal data is transferred outside India, We take reasonable steps to ensure it continues to be protected in line with this Policy and applicable law, including the DPDP Act. Our main processors, Google Firebase and PostHog, currently store data on servers located in the United States.


13. BUSINESS TRANSFER

If CookEzee is involved in a merger, acquisition, financing, reorganisation, sale of assets, or insolvency, Your personal data may be transferred to a successor or acquirer as part of that transaction. We will require the recipient to honour this Policy and will notify You of any material change in how Your data is handled.


14. THIRD-PARTY LINKS

The Platform may link to third-party websites or services (for example, Our social media pages, app stores, or payment pages). We are not responsible for the privacy practices or content of those third parties. Please review their policies before sharing information with them.


15. CHANGES TO THIS POLICY

We may update this Policy from time to time. Material changes will be notified in-app or by other reasonable means. Continued use after an update constitutes acknowledgement.